CVE-2018-1000006
Summary
| CVE | CVE-2018-1000006 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-24 23:29:00 UTC |
| Updated | 2023-11-07 02:51:00 UTC |
| Description | GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Exodus Wallet (ElectronJS Framework) - Remote Code Execution - Windows remote Exploit |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Third Party Advisory, VDB Entry |
| Protocol Handler Vulnerability Fix | Electron Blog |
CONFIRM |
electronjs.org |
Mitigation, Third Party Advisory |
| Release electron v1.8.2-beta.4 · electron/electron · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| Exploiting Electron RCE in Exodus wallet – wflki – Medium |
MISC |
medium.com |
Exploit, Issue Tracking, Third Party Advisory |
| Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit) - Windows remote Exploit |
EXPLOIT-DB |
www.exploit-db.com |
|
| Exploiting Electron RCE in Exodus wallet – wflki – Medium |
|
medium.com |
|
| Electron CVE-2018-1000006 Remote Code Execution Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982325 Nodejs (npm) Security Update for electron (GHSA-w222-53c6-c86p)